Unauthenticated Remote Code Execution
Vulnerability Description
An unauthenticated attacker on the WAN interface, with the ability to intercept Dynamic DNS (DDNS) traffic between DDNS services and the modem, could manipulate specific responses to include code that forces a buffer overflow on the modem. Customers that have not enabled Dynamic DNS on their modem are not vulnerable.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-6199
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Quentin Kaiser from ONEKEY Research Labs
Affected Vendor
ViaSat
View all reports →